You currently have javascript disabled. Several functions may not work. Please re-enable javascript to access full functionality.

Register a free account to unlock additional features at BleepingComputer.com

Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Backdoor.bifrose And Possible Others?

I found a nasty in my HJT log called NTSpool.exe I still have it on my system and wanted to know if someone could advise me first before moving forward. Also if their's anything else I should remove from the log.

I upgraded the version of HJT and ntspool.exe does not appear to be there anymore? If someone can review the log that would be great.

BC AdBot (Login to Remove)

Welcome to the BleepingComputer HijackThis Logs and Analysis forum XillianIXMy name is Richie and i'll be helping you to fix your problems.

If you have previously downloaded ComboFix,please delete that version now.

*Warning*You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert. It is intended by its creator to be used under the guidance and supervision of an expert,not for private use. Using this tool incorrectly could lead to your system becoming unusable.

Now download Combofix and save to your desktop:Note: It is important that it is saved directly to your desktopClose any open browsers.Disconnect from the Internet. Double click on combofix.exe and follow the prompts. When it's finished it will produce a log. Post the entire contents of C:\ComboFix.txt into your next reply. Note: Do not mouseclick combofix's window while it's running. That may cause the program to freeze/hang. Do NOT post the ComboFix-quarantined-files.txt unless I ask.*Note*In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.